Currently when SSP is unable to verify the signature on an assertion or an authnrequest it displays an error like "Unable to validate Signature". This message is accurate, but means the support request we/Cirrus receive always start with "What does this mean?", and we would like to improve that process by providing a more informative message. I believe this could be useful to the SSP project in general, since the mailing list/slack do get similar questions.
We propose improving the error messaging to:
- Indicate the affected SP or IdP entityId
- Provide corrective instructions/hints
For our own theme's error template we want to know the entityId and if we are processing a saml response or an authn request when the error happened.
@ioigoume is figuring out how this could work.
Currently we are thinking of adjustment to Message checkSign to wrap $lastException to include the entityId and SignedElement class to use in an improved message.
An area I have little experience is how to tie this into the error page to display an informative message. I see some areas where SSP subclasses SimpleSAML\Error\Exception, and some we use Error class and some times just use SimpleSAML\Error\Exception directly. Any guidance on this would be appreciated.
Lastly, what would the default, more informative message say? We were thinking something like " is signing messages with a new key. Please provide your admin with the new metadata for "
Please let us know if this seems useful for the project, and Ioannis can build out this improvement.
Currently when SSP is unable to verify the signature on an assertion or an authnrequest it displays an error like "Unable to validate Signature". This message is accurate, but means the support request we/Cirrus receive always start with "What does this mean?", and we would like to improve that process by providing a more informative message. I believe this could be useful to the SSP project in general, since the mailing list/slack do get similar questions.
We propose improving the error messaging to:
For our own theme's error template we want to know the entityId and if we are processing a saml response or an authn request when the error happened.
@ioigoume is figuring out how this could work.
Currently we are thinking of adjustment to Message checkSign to wrap
$lastExceptionto include the entityId and SignedElement class to use in an improved message.An area I have little experience is how to tie this into the error page to display an informative message. I see some areas where SSP subclasses
SimpleSAML\Error\Exception, and some we use Error class and some times just useSimpleSAML\Error\Exceptiondirectly. Any guidance on this would be appreciated.Lastly, what would the default, more informative message say? We were thinking something like " is signing messages with a new key. Please provide your admin with the new metadata for "
Please let us know if this seems useful for the project, and Ioannis can build out this improvement.